Skip to main content

Deploy a role to trust child accounts

You can link multiple child accounts in bulk to the root account in the Virtana platform.

Prerequisites

  • You have deployed the CloudFormation template to the root account.

  • You have downloaded the CloudFormation template for linking child accounts.

  • You have permissions to deploy CloudFormation stacks in the target AWS accounts.

Note

To enable the root account of your organization to trust child accounts, Virtana recommends using StackSets.

  1. Note

    Verify that the CloudFormation template file is accurate and accessible before you upload it.

    Upload the CloudFormation template to the AWS CloudFormation console.

    AWS CloudFormation console showing the template upload screen with the child-account template selected.
  2. Click Next.

  3. Configure the following required parameters.

    CloudFormation parameters screen showing the Account ID, External ID, and Role Name fields.
    • Account ID: Enter the AWS account ID of the Virtana account that you intend to trust. Verify that the account ID is correct to avoid configuration issues.

    • External ID: Enter the customer organization ID. This parameter adds an additional layer of security by ensuring that requests are authenticated and originate only from your organization.

    • Role Name: Enter the same role name that you configured when running the CloudFormation template on the root account. A default role name is provided, but you can customize it if needed. The role name must be identical across the root account and the roles created via the StackSet for linked accounts. A mismatch can cause deployment failure.

  4. Click Next.

  5. Choose the settings that meet your organizational requirements.

    CloudFormation stack options screen with capability acknowledgment and stack-failure settings.
  6. Click Next.

  7. After the CloudFormation stack deployment finishes, verify that the roles have been created in the child accounts.

    Note

    You can verify the trust relationship from Virtana. For more information, see Adding Linked Accounts in Bulk. To stop monitoring a child account, you must manually remove the assigned role from that account.

Related topics

Primary Account vs Linked Account in AWS

Adding Linked AccountsAdding Linked Accounts

Adding Linked Accounts in Bulk